RE: non-local admin revisited

2011-07-29 Thread Hilderbrand, Doug
:kz2...@googlemail.com] Sent: Wednesday, July 20, 2011 2:33 AM To: NT System Admin Issues Subject: Re: non-local admin revisited I run with a non-privileged account on my Win7 workstation and have an admin account that I supply to UAC whenever I need to run anything with higher-level privileges. This works g

Re: non-local admin revisited

2011-07-21 Thread Andrew S. Baker
:) * * *ASB* *http://about.me/Andrew.S.Baker* *Harnessing the Advantages of Technology for the SMB market… * On Wed, Jul 20, 2011 at 9:06 PM, Ben Scott wrote: > On Wed, Jul 20, 2011 at 7:02 AM, Andrew S. Baker > wrote: > >> I'd still much rather be required to enter a password for privile

Re: non-local admin revisited

2011-07-20 Thread Ben Scott
On Wed, Jul 20, 2011 at 7:02 AM, Andrew S. Baker wrote: >> I'd still much rather be required to enter a password for privileged >> operations. Being one click away from system privilege is scary for a >> number of reasons. > > Either way is easily faciliated depending upon one's requirements.

Re: non-local admin revisited

2011-07-20 Thread Jon Harris
I am with Ben on this. $Dayjob$ has it like Andrew has it. Jon On Wed, Jul 20, 2011 at 12:07 AM, Ben Scott wrote: > On Tue, Jul 19, 2011 at 9:36 PM, Kennedy, Jim > wrote: > > Hmmm, I like this. With UAC on there is validity to running as > > an admin all the time, IF you only have admin on yo

Re: non-local admin revisited

2011-07-20 Thread Anders Blomgren
es not add…it replaces.*** > * > > ** ** > > *From:* David Lum [mailto:david@nwea.org] > *Sent:* Tuesday, July 19, 2011 1:32 PM > > *To:* NT System Admin Issues > *Subject:* RE: non-local admin revisited > > ** ** > > A local admin account? So 50 IT folks would have 50

RE: non-local admin revisited

2011-07-20 Thread Matthew B Ames
and if that fails, then simply remove the users hands :) From: James Rankin [mailto:kz2...@googlemail.com] Sent: 20 July 2011 17:02 To: NT System Admin Issues Subject: Re: non-local admin revisited It is if they have to type some credentials in. If they have admin accounts and will type their

Re: non-local admin revisited

2011-07-20 Thread Jonathan Link
matter how much you warn them, a dimmed UAC screen >> isn't going to inhibit their impulses. >> >> > -Original Message- >> > From: Kennedy, Jim [mailto:kennedy...@elyriaschools.org] >> > Sent: Tuesday, July 19, 2011 6:37 PM >> > To:

Re: non-local admin revisited

2011-07-20 Thread James Rankin
m: Kennedy, Jim [mailto:kennedy...@elyriaschools.org] > > Sent: Tuesday, July 19, 2011 6:37 PM > > To: NT System Admin Issues > > Subject: RE: non-local admin revisited > > > > > > Hmmm, I like this. With UAC on there is validity to running as an > admin all the

RE: non-local admin revisited

2011-07-20 Thread Jim Dandy
-- > From: Kennedy, Jim [mailto:kennedy...@elyriaschools.org] > Sent: Tuesday, July 19, 2011 6:37 PM > To: NT System Admin Issues > Subject: RE: non-local admin revisited > > > Hmmm, I like this. With UAC on there is validity to running as an admin all the > time, IF you

RE: non-local admin revisited

2011-07-20 Thread David Lum
Admin Issues Subject: RE: non-local admin revisited What's your reason for wanting to do it? From: David Lum [david@nwea.org] Sent: 19 July 2011 6:10 PM To: NT System Admin Issues Subject: non-local admin revisited How do you bigger org's handle IT st

Re: non-local admin revisited

2011-07-20 Thread Andrew S. Baker
Either way is easily faciliated depending upon one's requirements. * * *ASB* *http://about.me/Andrew.S.Baker* *Harnessing the Advantages of Technology for the SMB market… * On Wed, Jul 20, 2011 at 12:07 AM, Ben Scott wrote: > On Tue, Jul 19, 2011 at 9:36 PM, Kennedy, Jim > wrote: > > Hmmm,

Re: non-local admin revisited

2011-07-20 Thread James Rankin
> but AFAIK it overwrites the local admins group rather than appending it > which I’d find a little (pardon the pun) restrictive. > > ** ** > > Paul > > > > *From:* Andrew S. Baker [mailto:asbz...@gmail.com] > *Sent:* 20 July 2011 01:08 > > *To:* NT Syste

RE: non-local admin revisited

2011-07-20 Thread Paul Hutchings
oo much with restricted groups but AFAIK it overwrites the local admins group rather than appending it which I'd find a little (pardon the pun) restrictive. Paul From: Andrew S. Baker [mailto:asbz...@gmail.com] Sent: 20 July 2011 01:08 To: NT System Admin Issues Subject: Re: non-local admin

Re: non-local admin revisited

2011-07-19 Thread Ben Scott
On Tue, Jul 19, 2011 at 9:36 PM, Kennedy, Jim wrote: > Hmmm, I like this. With UAC on there is validity to running as > an admin all the time, IF you only have admin on your own > machine. I'd still much rather be required to enter a password for privileged operations. Being one click away fro

Re: non-local admin revisited

2011-07-19 Thread Richard Stovall
twist Andrew. > > > > From: Andrew S. Baker [asbz...@gmail.com] > Sent: Tuesday, July 19, 2011 8:11 PM > To: NT System Admin Issues > Subject: Re: non-local admin revisited > > > IT members have Win7 and have local admin access of their own machi

RE: non-local admin revisited

2011-07-19 Thread Kennedy, Jim
, July 19, 2011 8:11 PM To: NT System Admin Issues Subject: Re: non-local admin revisited IT members have Win7 and have local admin access of their own machines, but with UAC enabled at the default level. ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~

Re: non-local admin revisited

2011-07-19 Thread Andrew S. Baker
user/id passwords they’ll all know anyway to do > “runas”? > > ** ** > > *From:* Kennedy, Jim [mailto:kennedy...@elyriaschools.org] > *Sent:* Tuesday, July 19, 2011 10:54 AM > > *To:* NT System Admin Issues > *Subject:* RE: non-local admin revisited > > ** **

Re: non-local admin revisited

2011-07-19 Thread Andrew S. Baker
--- > *From:* David Lum [david@nwea.org] > *Sent:* 19 July 2011 6:10 PM > > *To:* NT System Admin Issues > *Subject:* non-local admin revisited > > How do you bigger org’s handle IT staff (DBA’s and the like) not being > local admins on their systems? Invariably they

RE: non-local admin revisited

2011-07-19 Thread James Hill
That's my preference. From: Kennedy, Jim [mailto:kennedy...@elyriaschools.org] Sent: Wednesday, 20 July 2011 3:54 AM To: NT System Admin Issues Subject: RE: non-local admin revisited Create a domain group called IT Local Admins and add the domain IT Admin accounts you create to it. The

RE: non-local admin revisited

2011-07-19 Thread Paul Hutchings
What's your reason for wanting to do it? From: David Lum [david@nwea.org] Sent: 19 July 2011 6:10 PM To: NT System Admin Issues Subject: non-local admin revisited How do you bigger org’s handle IT staff (DBA’s and the like) not being local admins on

RE: non-local admin revisited

2011-07-19 Thread Ray
You're going to create user/id passwords they'll all know anyway to do "runas"? From: Kennedy, Jim [mailto:kennedy...@elyriaschools.org] Sent: Tuesday, July 19, 2011 10:54 AM To: NT System Admin Issues Subject: RE: non-local admin revisited Create a domain group ca

RE: non-local admin revisited

2011-07-19 Thread Ziots, Edward
Subject: non-local admin revisited How do you bigger org's handle IT staff (DBA's and the like) not being local admins on their systems? Invariably they are used to throwing on whatever they want and in some ways this helps the Help desk so they're not called to install stuff the u

RE: non-local admin revisited

2011-07-19 Thread Kennedy, Jim
. From: David Lum [mailto:david@nwea.org] Sent: Tuesday, July 19, 2011 1:32 PM To: NT System Admin Issues Subject: RE: non-local admin revisited A local admin account? So 50 IT folks would have 50 different local admin accounts? Other than the deny log on locally what keeps them from creating an

Re: non-local admin revisited

2011-07-19 Thread Candee
:20 AM > > To: NT System Admin Issues > > Subject: RE: non-local admin revisited > > > > +1 > > > > From: Don Ely [mailto:don....@gmail.com] > > Sent: Tuesday, July 19, 2011 1:19 PM > > To: NT System Admin Issues > > Subject: Re: non-local admin re

Re: non-local admin revisited

2011-07-19 Thread Jonathan Link
ave. > > ** ** > > *From:* Kennedy, Jim [mailto:kennedy...@elyriaschools.org] > *Sent:* Tuesday, July 19, 2011 10:20 AM > > *To:* NT System Admin Issues > *Subject:* RE: non-local admin revisited > > ** ** > > +1 > > ** ** > > *From:* Don Ely [mailto

RE: non-local admin revisited

2011-07-19 Thread Don Ely
t; > Win 7 makes alternate credentials easy enough at least... > > Dave. > > From: Kennedy, Jim [mailto:kennedy...@elyriaschools.org] > Sent: Tuesday, July 19, 2011 10:20 AM > To: NT System Admin Issues > Subject: RE: non-local admin revisited > > +1 > > From: Don Ely

RE: non-local admin revisited

2011-07-19 Thread David Lum
...@elyriaschools.org] Sent: Tuesday, July 19, 2011 10:20 AM To: NT System Admin Issues Subject: RE: non-local admin revisited +1 From: Don Ely [mailto:don@gmail.com] Sent: Tuesday, July 19, 2011 1:19 PM To: NT System Admin Issues Subject: Re: non-local admin revisited Provide them with an

RE: non-local admin revisited

2011-07-19 Thread Kennedy, Jim
+1 From: Don Ely [mailto:don@gmail.com] Sent: Tuesday, July 19, 2011 1:19 PM To: NT System Admin Issues Subject: Re: non-local admin revisited Provide them with an admin account and show them how to use "run-as"... I also disable logon locally where I can get away with it so

Re: non-local admin revisited

2011-07-19 Thread Don Ely
Provide them with an admin account and show them how to use "run-as"... I also disable logon locally where I can get away with it so they don't cheat... On Tue, Jul 19, 2011 at 10:10 AM, David Lum wrote: > How do you bigger org’s handle IT staff (DBA’s and the like) not being > local admins on